Deployment Architecture

Heavy Forwarder TcpOutputProc output queue is not sending to AIO

stromy
Loves-to-Learn Lots

Dears

Thanks A lot for helping Already.

i have 2 heavy forwarders(HF) and one Indexer(AIO)
Im facing this issue for the first time,(HF-1) is not forwarding logs to AIO , though HF-2 is sending normally to the AIO and i can search the logs .

The thing is i tried telnet on both sides it did connect, it seems there is no network problem, firewall is down, SElinux is down
below are some logs on the HF-1

03-14-2020 02:00:54.097 +0300 WARN TcpOutputProc - The TCP output processor has paused the data flow. Forwarding to output group primary_indexers has been blocked for 230 seconds. This will probably stall the data flow towards indexing and other network outputs. Review the receiving system's health in the Splunk Monitoring Console. It is probably not accepting data.

03-14-2020 01:23:22.056 +0300 WARN TcpOutputProc - Read operation timed out expecting ACK from 10.244.2.100:9997 in 300 seconds.

0 Karma
Get Updates on the Splunk Community!

Tech Talk Recap | Mastering Threat Hunting

Mastering Threat HuntingDive into the world of threat hunting, exploring the key differences between ...

Observability for AI Applications: Troubleshooting Latency

If you’re working with proprietary company data, you’re probably going to have a locally hosted LLM or many ...

Splunk AI Assistant for SPL vs. ChatGPT: Which One is Better?

In the age of AI, every tool promises to make our lives easier. From summarizing content to writing code, ...